Get instant support with our search!
Microsoft 365 Direct Message Injection Setup Guide
The Microsoft 365 Direct Message Injection feature is currently in Private Preview. Please contact your Customer Success Manager if you wish to be included in the preview.
This guide is for Microsoft 365 Global Administrators or Privileged Role Administrators. It should take approximately 15–20 minutes to complete. If you need assistance at any point, please contact your MetaCompliance Support representative.
The native Microsoft Report Button is not currently supported with DMI. A future update is planned to introduce support.
Overview
MetaCompliance Phish can deliver phishing simulation emails directly into your users’ Exchange Online inboxes using Microsoft 365 Direct Message Injection (DMI). This bypasses inbound gateway filtering, ensuring that simulation emails are delivered reliably and that your phishing reports reflect genuine user behaviour only.
To enable this, MetaCompliance requires your Microsoft 365 administrator to grant our application consent within your tenant. This is a one-time setup and MetaCompliance will guide you through every step.
When to use DMI
DMI use will help if you are:
- Experiencing problems with email security software filtering out simulations before they reach a user’s mailbox
- Finding it difficult to keep up to date with Allowlisting/Whitelisting to ensure simulations reach a user’s mailbox
DMI use won’t help in the following scenarios:
- Security policies preventing the automatic download of imagery in simulation emails
- Security tools that process emails within the user’s inbox post-delivery – you’ll still need to configure these tools to accept MetaCompliance simulations
What you will need
- Global Administrator or Privileged Role Administrator access to your Microsoft 365 tenant
- The admin consent URL provided by your MetaCompliance support representative
Permissions required
MetaCompliance’s application needs to be granted the Microsoft Graph Mail.ReadWrite permission. Microsoft does not offer a narrower or alternative scope for Direct Message Injection, so this permission is needed – there is no way to configure DMI without it.
Mail.ReadWrite gives MetaCompliance access to create, read, update and delete mail in your users’ inboxes. We’ll only ever use the create privilege to insert simulation emails into user mailboxes.
If you plan to only ever send phishing simulations to a subset of users, it’s possible to scope the permissions to a subset of mailboxes – take a look at our Microsoft 365 DMI Mailbox Scoping Guide for one way you can do this.
Step 1 – Grant admin consent for the MetaCompliance application
Your MetaCompliance support representative will provide you with an admin consent URL specific to your organisation. It will look like this:
https://login.microsoftonline.com/{your-tenant-id}/adminconsent?client_id={metacompliance-app-id}
- Copy the URL provided by your MetaCompliance support representative
- Open it in a browser while signed in with your Global Administrator or Privileged Role Administrator account
- Review the permissions requested and click Accept. You will be redirected to a confirmation page once consent has been granted successfully.
Note: Only a Global Administrator or Privileged Role Administrator can complete this step. If you see a permissions error, confirm your account has the required role assigned.
Step 2 – Notify your MetaCompliance support representative
Once you have completed Step 1, please notify your MetaCompliance support representative. They will:
- Update your account configuration to enable Direct Message Injection delivery
- Run a test injection to verify the setup is working correctly before your first live simulation
Removing access
If you wish to remove MetaCompliance’s access at any time, you can revoke the admin consent by navigating to Microsoft Entra ID > Enterprise applications, locating the MetaCompliance application, and deleting it. Please notify your MetaCompliance support representative if you do this, as phishing simulations for your organisation will not revert to standard SMTP delivery automatically and will fail until your delivery method is reconfigured.
Frequently asked questions
Do I need to create an application registration myself?
No. MetaCompliance manages the application registration on our side. You only need to grant consent for our existing application within your Microsoft 365 tenant using the URL we provide, and optionally apply the mailbox scoping policy.
Why does MetaCompliance need Mail.ReadWrite?
Mail.ReadWrite is the Microsoft Graph API permission that allows MetaCompliance to insert the simulation emails directly into Exchange Online mailboxes. Microsoft does not publish a create-only mail scope, so Mail.ReadWrite is the narrowest permission that supports DMI. We only ever use the create privilege.
We are on a hybrid Exchange deployment – does this work for us?
Microsoft 365 DMI requires mailboxes to be hosted in Exchange Online. If some or all of your mailboxes are hosted on-premises as part of a hybrid Exchange deployment, DMI cannot be used.
What happens if a simulation email fails to deliver?
If injection fails for any reason, MetaCompliance’s system will log the failure and your support representative will be notified. Depending on your account configuration, delivery may fall back to standard SMTP or the send may be retried.